On Wed, Apr 21, 2010 at 01:22:35PM +0530, Arjun Nanjundappa wrote:

> So, I have started to write a dissector for decoding EcdoRpcExt2 
> message. But since the message is compressed , I am getting a 
> compressed message in the following format for the Hex-dump message.

> Please provide me info as I how I need to decompress and decode the 
> message .

Are you sure it's compressed?  I am not very familiar with that 
protocol, but it looks like Microsoft's 0xA5 XOR against the real data 
obfuscation.


-- 
Steve
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <[email protected]>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:[email protected]?subject=unsubscribe

Reply via email to